Orkes Conductor unauthenticated RCE via inline workflow definitions
Unauthenticated RCE in Orkes Conductor via crafted inline workflow definitions. CVSS 9.8 critical; active exploitation confirmed.
- Vendor
- Orkes
- Product
- Orkes Conductor
- CVSS
- 9.8
- EPSS (exploit probability)
- 9.3%
- Status
- exploited-in-wild
- Published
An unauthenticated attacker can execute arbitrary code on Orkes Conductor servers by submitting crafted inline workflow definitions to the API. No authentication is required to trigger the flaw.
Active exploitation was confirmed by SecurityWeek as of September 17, 2026. Refer to the NVD entry and the Orkes security advisory for specific affected version ranges and available patches. If a patch is not yet available in your environment, restrict network access to the Conductor API to trusted sources and treat any anomalous workflow execution as a potential incident.
